First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Shadow IT Assessment Workshop (Remote)
Training

Shadow IT Assessment Workshop (Remote) — Cloud App Discovery & Control

Shadow IT Assessment Workshop (Remote) is a 2-day remote training engagement for organizations that want to discover and assess cloud applications and services being used without the IT department’s knowledge. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud app usage from the organization’s network and provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control Road Map.

Timeline 2 daysService owner Mike MackeyOffice 365microsoft 365

What this engagement is

Shadow IT refers to applications and infrastructure that are managed and used without the enterprise IT department’s knowledge. This remote workshop helps customers discover Shadow IT by using Microsoft Defender for Cloud Apps — managed in the unified Microsoft Defender portal — to evaluate cloud application and service usage from within the organization’s network. The engagement focuses on understanding the customer’s cloud security objectives, comparing them with actual cloud usage, and producing findings and recommendations for improving visibility and control. This service is listed for Office 365 and Microsoft 365 as Training.

Success criteria

01Deliver the Shadow IT Assessment, including good security principles covering people, process, and technology solutions.
02Improve the security posture when it comes to usage of cloud applications and services.
03Base the assessment on the discovery of usage of cloud applications and services.

What you receive

Kickoff Presentation: an overview of the engagement covering vision and objectives, requirements, and next steps.
Pre-Assessment Questionnaire: a questionnaire containing questions on cloud usage/adoption, security requirements and objectives, regulations, and frameworks.
Shadow IT Discovery Report: a document containing a list of discovered possible Shadow IT usage and recommendations for further investigation.
Cloud Usage Visibility and Control Road Map: a prioritized, actionable road map for addressing discovered cloud usage, especially its Shadow IT aspect, including mapping capabilities of Microsoft Defender for Cloud Apps in a customer environment.

How the work unfolds

Remote kickoff meeting

The Shadow IT Assessment typically consists of an up to two-hour remote kickoff meeting followed by remote assessment workshops. The kickoff includes an introduction to the engagement covering objectives, flow, responsibilities, and governance, and IT Partner provides and explains the pre-assessment questionnaire to the customer.

Webinar 1 — Education & Setup

Review the questionnaire, which should be ready by the time of the webinar, to get mutual understanding, especially around the customer’s cloud usage and associated security objectives and requirements. Provide education and readiness on Microsoft Defender for Cloud Apps.

Webinar 2 — Exploration & Discovery

Review the Defender for Cloud Apps report(s) with the customer, explore specific use cases of cloud usage in the portal, create the final report from the engagement highlighting discovered cases of Shadow IT, and create the Cloud Usage Visibility and Control Road Map.

Webinar 3 — Review & Road Map

Present and discuss the final report from the engagement, highlighting discovered cases of Shadow IT, meaning usage of unapproved cloud applications or services. Review the Cloud Usage Visibility and Control Road Map.

Prerequisites

Microsoft 365 tenant with microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation.
Access to logs from customer firewalls or proxies.
Log Collector should be configured and ready to work, per Microsoft's Defender for Cloud Apps Log Collector documentation.

Who does what

IT Partner

  • Gain an understanding of customer's cloud security objectives and requirements toward cloud usage and verify them against real usage of cloud applications and services
  • Provide guidance, recommendations, and best practices on how to successfully use Microsoft Defender for Cloud Apps to mitigate security threats that are associated with usage of cloud application and services
  • Provide a prioritized and actionable road map for the customer, containing proposed actions based on user impact and implementation cost
  • Map Microsoft Defender for Cloud Apps capabilities and partner services to assessment findings, taking into account customer's security objectives and requirements

Your team

  • Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
  • Access to people: This includes access to knowledgeable customer personnel, including business user representatives, and access to funding (if additional budget is needed to deliver project scope), as well as access to knowledgeable personnel who manage the firewalls, can provide credentials for log extraction, and can alter firewall rules if necessary.
  • Access to systems: This includes access to all necessary customer work locations, networks, systems, and applications (remote and onsite)

What's not included

Remediation or enforcement of Shadow IT findings, including blocking applications, creating conditional access controls, or implementing sanction/unsanction policies.
Production deployment, tuning, or long-term operation of Microsoft Defender for Cloud Apps beyond the assessment and workshop activities described.
Procurement of Microsoft 365, Microsoft Defender for Cloud Apps, E5 licenses, trial subscriptions, firewall/proxy products, or any third-party tools.
IT Partner performing firewall, proxy, network, endpoint, or identity infrastructure changes; the customer may still need to make log collection or access-related changes if necessary for the assessment.
Custom connectors, custom data engineering, SIEM integration, SOC runbook development, or automated remediation workflow development.
Comprehensive security architecture review, penetration testing, compliance audit, legal review, data classification program, or full cloud governance implementation.
Investigation of every individual user action or application transaction; findings are based on available discovery data, logs, and workshop analysis.
Ongoing managed security monitoring, incident response, alert triage, or post-workshop administration unless contracted separately.

Limitations & technical notes

!An on-site form of the workshop (4 consulting days, 3 days on-site) is available as a separate service.

Frequently asked questions

What is the Shadow IT Assessment Workshop (Remote)?

The Shadow IT Assessment Workshop (Remote) is a 2-day remote training engagement that helps organizations discover and assess cloud applications and services being used without the IT department’s knowledge. IT Partner uses Microsoft Defender for Cloud Apps to evaluate cloud app usage from the organization’s network and provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control Road Map.

Who is this Shadow IT Assessment Workshop intended for?

This workshop is intended for organizations using Office 365 or Microsoft 365 that want better visibility and control over unapproved or unknown cloud application usage. It is especially relevant when IT leaders need to compare cloud security objectives with actual cloud usage discovered from network activity.

How long does the Shadow IT Assessment Workshop take?

The Shadow IT Assessment Workshop is a 2-day remote engagement. The stated plan includes a remote kickoff meeting and remote assessment webinars covering education, setup, exploration, discovery, final report review, and the road map.

What deliverables are included in the Shadow IT Assessment Workshop?

The workshop includes a kickoff presentation, a pre-assessment questionnaire, a Shadow IT Discovery Report, and a Cloud Usage Visibility and Control Road Map. The discovery report lists possible Shadow IT usage and recommendations for further investigation, while the road map prioritizes actions for improving cloud usage visibility and control.

What happens during the remote kickoff meeting?

The remote kickoff meeting typically lasts up to two hours and introduces the engagement objectives, flow, responsibilities, and governance. IT Partner also provides and explains the pre-assessment questionnaire so the customer can supply information about cloud adoption, security requirements, regulations, and frameworks.

What prerequisites are required before the Shadow IT Assessment Workshop?

The customer needs a Microsoft 365 tenant with microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation. The customer also needs access to firewall or proxy logs and should have the Log Collector configured and ready to work.

Does the workshop require Microsoft Defender for Cloud Apps?

Yes, Microsoft Defender for Cloud Apps is a prerequisite because the assessment uses it to evaluate cloud application and service usage from the organization's network. Microsoft Defender for Cloud Apps licensing for in-scope users — included in Microsoft 365 E5 and in the Microsoft 365 E5 Security add-on, or available standalone; a Microsoft trial can be used for evaluation.

What network or log access is needed for the assessment?

The assessment requires access to logs from customer firewalls or proxies because those logs support discovery of cloud application and service usage. The customer should also have the Log Collector configured and ready, and knowledgeable firewall personnel may need to provide credentials for log extraction or adjust firewall rules if necessary.

Will the Shadow IT Assessment Workshop cause downtime or user disruption?

No planned downtime is required — the workshop is a remote assessment based on Microsoft Defender for Cloud Apps, questionnaires, and firewall or proxy log analysis. Any operational impact from log collection, firewall access, or configuration changes is agreed with your network team before the engagement.

Does the workshop block or remove Shadow IT applications?

No. The workshop covers discovery, assessment, reporting, recommendations, and a prioritized road map. Blocking, removing, or remediating Shadow IT applications is not part of the 2-day workshop — enforcement actions and application controls are scoped separately with IT Partner.

What happens after the Shadow IT Assessment Workshop is completed?

After completion, the customer receives the final report and the Cloud Usage Visibility and Control Road Map for prioritizing next steps. Implementing the road map's actions is not included in the 2-day workshop; IT Partner can quote follow-on implementation work separately.

Is an onsite version of the Shadow IT Assessment Workshop available?

Yes — an on-site version of the Shadow IT Assessment Workshop (4 consulting days, 3 days on-site) is available as a separate service; this page describes the remote version.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,950 per project
2 days
Book a meeting